<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Commentaires sur : 4 outils pour analyser les logs de HiJackThis</title> <atom:link href="http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/feed" rel="self" type="application/rss+xml" /><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html</link> <description>Upgrade your mind</description> <lastBuildDate>Tue, 14 Feb 2012 00:28:00 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>Par : Aude</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-145080</link> <dc:creator>Aude</dc:creator> <pubDate>Mon, 10 May 2010 12:44:34 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-145080</guid> <description>C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\boucaut\Bureau\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://postarticles.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pucuy.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d&#039;aide de l&#039;Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &amp;Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe&quot;
O4 - HKLM\..\Run: [UCam_Menu] &quot;C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files\CyberLink\YouCam&quot; UpdateWithCreateOnce &quot;Software\CyberLink\YouCam\3.0&quot;
O4 - HKLM\..\Run: [YouCam Mirror Tray icon] &quot;C:\Program Files\CyberLink\YouCam\YouCamTray.exe&quot; /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe&quot;
O4 - HKLM\..\Run: [Firewall Administrating] C:\WINDOWS\infocard.exe
O4 - HKLM\..\Run: [sfagent] C:\Program Files\Fighters\SPAMfighter\sfagent.exe
O4 - HKLM\..\Run: [VFPROguard] C:\Program Files\Fighters\VIRUSfighter\VFPROTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe&quot;
O4 - HKCU\..\Run: [EPSON Stylus SX400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE /FU &quot;C:\WINDOWS\TEMP\E_S86.tmp&quot; /EF &quot;HKCU&quot;
O4 - HKCU\..\Run: [msnmsgr] &quot;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&quot; /background
O4 - HKCU\..\Run: [MSMSGS] &quot;C:\Program Files\Messenger\msmsgs.exe&quot; /background
O4 - HKCU\..\Run: [Steam] &quot;C:\Program Files\Steam\Steam.exe&quot; -silent
O4 - HKCU\..\Run: [Firewall Administrating] C:\WINDOWS\infocard.exe
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;
O4 - HKCU\..\Run: [BrowserChoice] &quot;C:\WINDOWS\system32\browserchoice.exe&quot; /run
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#039;SERVICE LOCAL&#039;)
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#039;SERVICE RÃ‰SEAU&#039;)
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#039;SYSTEM&#039;)
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#039;Default user&#039;)
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\boucaut\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra &#039;Tools&#039; menuitem: &amp;Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra &#039;Tools&#039; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra &#039;Tools&#039; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: AV Engine Scanning Service - Preventon Technologies Limited - C:/Program Files/Fichiers communs/Common Toolkit Suite/AVEngine/AVScanningService.exe
O23 - Service: Common Toolkit Service - SPAMfighter - C:\Program Files\Common Files\Common Toolkit Suite\FighterSuiteService.exe
O23 - Service: CSIScanner - Unknown owner - C:\Program Files\Prevx\prevx.exe (file missing)
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\Fighters\SPAMfighter\sfus.exe
--
End of file - 10193 bytes
Je n&#039;arrive pas Ã  l&#039;analyser Ã  partir de mon ordinateur du au virus IM55376.JPG-WWW.MYSPACE.COM.exe Pourriez vous m&#039;aider svp!</description> <content:encoded><![CDATA[<p>C:\Program Files\Internet Explorer\iexplore.exe<br
/> C:\Program Files\Internet Explorer\iexplore.exe<br
/> C:\Documents and Settings\boucaut\Bureau\HiJackThis.exe</p><p>R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a
target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=69157"  rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br
/> R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a
target="_blank" href="http://postarticles.net"  rel="nofollow">http://postarticles.net</a><br
/> R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a
target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=69157"  rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br
/> R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a
target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"  rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br
/> R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a
target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"  rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br
/> R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a
target="_blank" href="http://www.pucuy.com/"  rel="nofollow">http://www.pucuy.com/</a><br
/> R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens<br
/> O2 &#8211; BHO: AcroIEHelperStub &#8211; {18DF081C-E8AD-4283-A596-FA578C2EBDC3} &#8211; C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br
/> O2 &#8211; BHO: (no name) &#8211; {5C255C8A-E604-49b4-9D64-90988571CECB} &#8211; (no file)<br
/> O2 &#8211; BHO: Search Helper &#8211; {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} &#8211; C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br
/> O2 &#8211; BHO: Programme d&#8217;aide de l&#8217;Assistant de connexion Windows Live &#8211; {9030D464-4C02-4ABF-8ECC-5164760863C6} &#8211; C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br
/> O2 &#8211; BHO: Google Toolbar Helper &#8211; {AA58ED58-01DD-4d91-8333-CF10577473F7} &#8211; C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br
/> O2 &#8211; BHO: Google Toolbar Notifier BHO &#8211; {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} &#8211; C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll<br
/> O2 &#8211; BHO: Java(tm) Plug-In 2 SSV Helper &#8211; {DBC80044-A445-435b-BC74-9C25C1C588A9} &#8211; C:\Program Files\Java\jre6\bin\jp2ssv.dll<br
/> O2 &#8211; BHO: Windows Live Toolbar Helper &#8211; {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} &#8211; C:\Program Files\Windows Live\Toolbar\wltcore.dll<br
/> O2 &#8211; BHO: JQSIEStartDetectorImpl &#8211; {E7E6F031-17CE-4C07-BC86-EABFE594F69C} &#8211; C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br
/> O2 &#8211; BHO: EpsonToolBandKicker Class &#8211; {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} &#8211; C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br
/> O3 &#8211; Toolbar: EPSON Web-To-Page &#8211; {EE5D279F-081B-4404-994D-C6B60AAEBA6D} &#8211; C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll<br
/> O3 &#8211; Toolbar: Google Toolbar &#8211; {2318C2B1-4965-11d4-9B18-009027A5CD4F} &#8211; C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br
/> O3 &#8211; Toolbar: &amp;Windows Live Toolbar &#8211; {21FA44EF-376D-4D53-9B0F-8A89D3229068} &#8211; C:\Program Files\Windows Live\Toolbar\wltcore.dll<br
/> O4 &#8211; HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br
/> O4 &#8211; HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe<br
/> O4 &#8211; HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe<br
/> O4 &#8211; HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br
/> O4 &#8211; HKLM\..\Run: [QuickTime Task] &laquo;&nbsp;C:\Program Files\QuickTime\qttask.exe&nbsp;&raquo; -atboottime<br
/> O4 &#8211; HKLM\..\Run: [Adobe Reader Speed Launcher] &laquo;&nbsp;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [Adobe ARM] &laquo;&nbsp;C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [UCam_Menu] &laquo;&nbsp;C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe&nbsp;&raquo; &laquo;&nbsp;C:\Program Files\CyberLink\YouCam&nbsp;&raquo; UpdateWithCreateOnce &laquo;&nbsp;Software\CyberLink\YouCam\3.0&#8243;<br
/> O4 &#8211; HKLM\..\Run: [YouCam Mirror Tray icon] &laquo;&nbsp;C:\Program Files\CyberLink\YouCam\YouCamTray.exe&nbsp;&raquo; /s<br
/> O4 &#8211; HKLM\..\Run: [SunJavaUpdateSched] &laquo;&nbsp;C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [Firewall Administrating] C:\WINDOWS\infocard.exe<br
/> O4 &#8211; HKLM\..\Run: [sfagent] C:\Program Files\Fighters\SPAMfighter\sfagent.exe<br
/> O4 &#8211; HKLM\..\Run: [VFPROguard] C:\Program Files\Fighters\VIRUSfighter\VFPROTray.exe<br
/> O4 &#8211; HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br
/> O4 &#8211; HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden<br
/> O4 &#8211; HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &laquo;&nbsp;C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe&nbsp;&raquo;<br
/> O4 &#8211; HKCU\..\Run: [EPSON Stylus SX400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE /FU &laquo;&nbsp;C:\WINDOWS\TEMP\E_S86.tmp&nbsp;&raquo; /EF &laquo;&nbsp;HKCU&nbsp;&raquo;<br
/> O4 &#8211; HKCU\..\Run: [msnmsgr] &laquo;&nbsp;C:\Program Files\Windows Live\Messenger\msnmsgr.exe&nbsp;&raquo; /background<br
/> O4 &#8211; HKCU\..\Run: [MSMSGS] &laquo;&nbsp;C:\Program Files\Messenger\msmsgs.exe&nbsp;&raquo; /background<br
/> O4 &#8211; HKCU\..\Run: [Steam] &laquo;&nbsp;C:\Program Files\Steam\Steam.exe&nbsp;&raquo; -silent<br
/> O4 &#8211; HKCU\..\Run: [Firewall Administrating] C:\WINDOWS\infocard.exe<br
/> O4 &#8211; HKCU\..\Run: [swg] &laquo;&nbsp;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&nbsp;&raquo;<br
/> O4 &#8211; HKCU\..\Run: [BrowserChoice] &laquo;&nbsp;C:\WINDOWS\system32\browserchoice.exe&nbsp;&raquo; /run<br
/> O4 &#8211; HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#8216;SERVICE LOCAL&#8217<img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_wink.gif" alt="" /><br
/> O4 &#8211; HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#8216;SERVICE RÃ‰SEAU&#8217<img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_wink.gif" alt="" /><br
/> O4 &#8211; HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#8216;SYSTEM&#8217<img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_wink.gif" alt="" /><br
/> O4 &#8211; HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User &#8216;Default user&#8217<img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_wink.gif" alt="" /><br
/> O4 &#8211; Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe<br
/> O4 &#8211; Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\boucaut\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe<br
/> O8 &#8211; Extra context menu item: Google Sidewiki&#8230; &#8211; res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html<br
/> O9 &#8211; Extra button: Ajout Direct &#8211; {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} &#8211; C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br
/> O9 &#8211; Extra &#8216;Tools&#8217; menuitem: &amp;Ajout Direct dans Windows Live Writer &#8211; {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} &#8211; C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br
/> O9 &#8211; Extra button: (no name) &#8211; {e2e2dd38-d088-4134-82b7-f2ba38496583} &#8211; C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br
/> O9 &#8211; Extra &#8216;Tools&#8217; menuitem: @xpsp3res.dll,-20001 &#8211; {e2e2dd38-d088-4134-82b7-f2ba38496583} &#8211; C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br
/> O9 &#8211; Extra button: Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:\Program Files\Messenger\msmsgs.exe<br
/> O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Windows Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:\Program Files\Messenger\msmsgs.exe<br
/> O16 &#8211; DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) &#8211; <a
target="_blank" href="http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab"  rel="nofollow">http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab</a><br
/> O16 &#8211; DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) &#8211; <a
target="_blank" href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab"  rel="nofollow">http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab</a><br
/> O16 &#8211; DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} &#8211; <a
target="_blank" href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"  rel="nofollow">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br
/> O23 &#8211; Service: AV Engine Scanning Service &#8211; Preventon Technologies Limited &#8211; C:/Program Files/Fichiers communs/Common Toolkit Suite/AVEngine/AVScanningService.exe<br
/> O23 &#8211; Service: Common Toolkit Service &#8211; SPAMfighter &#8211; C:\Program Files\Common Files\Common Toolkit Suite\FighterSuiteService.exe<br
/> O23 &#8211; Service: CSIScanner &#8211; Unknown owner &#8211; C:\Program Files\Prevx\prevx.exe (file missing)<br
/> O23 &#8211; Service: Service Google Update (gupdate) (gupdate) &#8211; Google Inc. &#8211; C:\Program Files\Google\Update\GoogleUpdate.exe<br
/> O23 &#8211; Service: Google Software Updater (gusvc) &#8211; Google &#8211; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br
/> O23 &#8211; Service: Java Quick Starter (JavaQuickStarterService) &#8211; Sun Microsystems, Inc. &#8211; C:\Program Files\Java\jre6\bin\jqs.exe<br
/> O23 &#8211; Service: LightScribeService Direct Disc Labeling Service (LightScribeService) &#8211; Hewlett-Packard Company &#8211; C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe<br
/> O23 &#8211; Service: NBService &#8211; Nero AG &#8211; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br
/> O23 &#8211; Service: NMIndexingService &#8211; Nero AG &#8211; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe<br
/> O23 &#8211; Service: SPAMfighter Update Service &#8211; SPAMfighter ApS &#8211; C:\Program Files\Fighters\SPAMfighter\sfus.exe</p><p>&#8211;<br
/> End of file &#8211; 10193 bytes</p><p>Je n&#8217;arrive pas Ã  l&#8217;analyser Ã  partir de mon ordinateur du au virus IM55376.JPG-WWW.MYSPACE.COM.exe Pourriez vous m&#8217;aider svp!</p> ]]></content:encoded> </item> <item><title>Par : Quentin</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-140706</link> <dc:creator>Quentin</dc:creator> <pubDate>Sat, 24 Apr 2010 16:23:44 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-140706</guid> <description>Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:26:02, on 24/04/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Users\Quentin\AppData\Local\Temp\Zfg.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Safari\Safari.exe
C:\Users\Quentin\AppData\Local\Temp\66xvxnh0.tmp\HiJackThis.exe
C:\Users\Quentin\AppData\Local\Temp\Zfh.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ig?hl=fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9666
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Programme d&#039;aide de l&#039;Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UpdateLBPShortCut] &quot;C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files\CyberLink\LabelPrint&quot; UpdateWithCreateOnce &quot;Software\CyberLink\LabelPrint\2.0&quot;
O4 - HKLM\..\Run: [CLMLServer] &quot;C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe&quot;
O4 - HKLM\..\Run: [UpdateP2GoShortCut] &quot;C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files\CyberLink\Power2Go&quot; UpdateWithCreateOnce &quot;SOFTWARE\CyberLink\Power2Go\6.0&quot;
O4 - HKLM\..\Run: [UpdatePDRShortCut] &quot;C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files\CyberLink\PowerDirector&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerDirector\7.0&quot;
O4 - HKLM\..\Run: [RemoteControl8] &quot;C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe&quot;
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] &quot;C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe&quot;
O4 - HKLM\..\Run: [UpdatePPShortCut] &quot;C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files\CyberLink\PowerProducer&quot; update &quot;Software\CyberLink\PowerProducer\5.0&quot;
O4 - HKLM\..\Run: [UpdatePSTShortCut] &quot;C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files\CyberLink\DVD Suite&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerStarter&quot;
O4 - HKLM\..\Run: [UCam_Menu] &quot;C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files\CyberLink\YouCam&quot; UpdateWithCreateOnce &quot;Software\CyberLink\YouCam\2.0&quot;
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [YVIBBBHA8C] C:\Users\Quentin\AppData\Local\Temp\Zfh.exe
O4 - Global Startup: BTTray.lnk = ?
O9 - Extra button: Envoyer Ã  OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra &#039;Tools&#039; menuitem: &amp;Envoyer Ã  OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra &#039;Tools&#039; menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: IntelÂ® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de lâ€™iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: IntelÂ® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Rezip - Unknown owner - C:\Windows\SYSTEM32\Rezip.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
--
End of file - 9872 bytes</description> <content:encoded><![CDATA[<p>Logfile of Trend Micro HijackThis v2.0.2<br
/> Scan saved at 18:26:02, on 24/04/2010<br
/> Platform: Windows Vista SP2 (WinNT 6.00.1906)<br
/> MSIE: Internet Explorer v8.00 (8.00.6001.18904)<br
/> Boot mode: Normal</p><p>Running processes:<br
/> C:\Windows\system32\Dwm.exe<br
/> C:\Windows\system32\taskeng.exe<br
/> C:\Windows\Explorer.EXE<br
/> C:\Users\Quentin\AppData\Local\Temp\Zfg.exe<br
/> C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br
/> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br
/> C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe<br
/> C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe<br
/> C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br
/> C:\Program Files\AVG\AVG9\avgtray.exe<br
/> C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br
/> C:\Program Files\iTunes\iTunesHelper.exe<br
/> C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br
/> C:\Windows\ehome\ehtray.exe<br
/> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br
/> C:\Windows\ehome\ehmsas.exe<br
/> C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe<br
/> C:\Program Files\Windows Media Player\wmpnscfg.exe<br
/> C:\Program Files\Safari\Safari.exe<br
/> C:\Users\Quentin\AppData\Local\Temp\66xvxnh0.tmp\HiJackThis.exe<br
/> C:\Users\Quentin\AppData\Local\Temp\Zfh.exe</p><p>R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve<br
/> R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a
target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"  rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br
/> R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a
target="_blank" href="http://www.google.fr/ig?hl=fr"  rel="nofollow">http://www.google.fr/ig?hl=fr</a><br
/> R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a
target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"  rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br
/> R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a
target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"  rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br
/> R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br
/> R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br
/> R1 &#8211; HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9666<br
/> R1 &#8211; HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;;*.local<br
/> R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br
/> R3 &#8211; URLSearchHook: UrlSearchHook Class &#8211; {00000000-6E41-4FD3-8538-502F5495E5FC} &#8211; C:\Program Files\Ask.com\GenericAskToolbar.dll<br
/> R3 &#8211; URLSearchHook: AVG Security Toolbar BHO &#8211; {A3BC75A2-1F87-4686-AA43-5347D756017C} &#8211; C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br
/> O1 &#8211; Hosts: ::1 localhost<br
/> O2 &#8211; BHO: AcroIEHelperStub &#8211; {18DF081C-E8AD-4283-A596-FA578C2EBDC3} &#8211; C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br
/> O2 &#8211; BHO: WormRadar.com IESiteBlocker.NavFilter &#8211; {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} &#8211; C:\Program Files\AVG\AVG9\avgssie.dll<br
/> O2 &#8211; BHO: (no name) &#8211; {5C255C8A-E604-49b4-9D64-90988571CECB} &#8211; (no file)<br
/> O2 &#8211; BHO: Groove GFS Browser Helper &#8211; {72853161-30C5-4D22-B7F9-0BBC1D38A37E} &#8211; C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br
/> O2 &#8211; BHO: Programme d&#8217;aide de l&#8217;Assistant de connexion Windows Live &#8211; {9030D464-4C02-4ABF-8ECC-5164760863C6} &#8211; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br
/> O2 &#8211; BHO: AVG Security Toolbar BHO &#8211; {A3BC75A2-1F87-4686-AA43-5347D756017C} &#8211; C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br
/> O2 &#8211; BHO: Google Toolbar Helper &#8211; {AA58ED58-01DD-4d91-8333-CF10577473F7} &#8211; C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br
/> O2 &#8211; BHO: Google Toolbar Notifier BHO &#8211; {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} &#8211; C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br
/> O2 &#8211; BHO: Ask Toolbar BHO &#8211; {D4027C7F-154A-4066-A1AD-4243D8127440} &#8211; C:\Program Files\Ask.com\GenericAskToolbar.dll<br
/> O2 &#8211; BHO: Java(tm) Plug-In 2 SSV Helper &#8211; {DBC80044-A445-435b-BC74-9C25C1C588A9} &#8211; C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)<br
/> O3 &#8211; Toolbar: AVG Security Toolbar &#8211; {CCC7A320-B3CA-4199-B1A6-9F516DD69829} &#8211; C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br
/> O3 &#8211; Toolbar: Google Toolbar &#8211; {2318C2B1-4965-11d4-9B18-009027A5CD4F} &#8211; C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br
/> O3 &#8211; Toolbar: DAEMON Tools Toolbar &#8211; {32099AAC-C132-4136-9E9A-4E364A424E17} &#8211; C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll<br
/> O3 &#8211; Toolbar: Ask Toolbar &#8211; {D4027C7F-154A-4066-A1AD-4243D8127440} &#8211; C:\Program Files\Ask.com\GenericAskToolbar.dll<br
/> O4 &#8211; HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br
/> O4 &#8211; HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br
/> O4 &#8211; HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br
/> O4 &#8211; HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br
/> O4 &#8211; HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br
/> O4 &#8211; HKLM\..\Run: [UpdateLBPShortCut] &laquo;&nbsp;C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe&nbsp;&raquo; &laquo;&nbsp;C:\Program Files\CyberLink\LabelPrint&nbsp;&raquo; UpdateWithCreateOnce &laquo;&nbsp;Software\CyberLink\LabelPrint\2.0&#8243;<br
/> O4 &#8211; HKLM\..\Run: [CLMLServer] &laquo;&nbsp;C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [UpdateP2GoShortCut] &laquo;&nbsp;C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe&nbsp;&raquo; &laquo;&nbsp;C:\Program Files\CyberLink\Power2Go&nbsp;&raquo; UpdateWithCreateOnce &laquo;&nbsp;SOFTWARE\CyberLink\Power2Go\6.0&#8243;<br
/> O4 &#8211; HKLM\..\Run: [UpdatePDRShortCut] &laquo;&nbsp;C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe&nbsp;&raquo; &laquo;&nbsp;C:\Program Files\CyberLink\PowerDirector&nbsp;&raquo; UpdateWithCreateOnce &laquo;&nbsp;Software\CyberLink\PowerDirector\7.0&#8243;<br
/> O4 &#8211; HKLM\..\Run: [RemoteControl8] &laquo;&nbsp;C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [PDVD8LanguageShortcut] &laquo;&nbsp;C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [UpdatePPShortCut] &laquo;&nbsp;C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe&nbsp;&raquo; &laquo;&nbsp;C:\Program Files\CyberLink\PowerProducer&nbsp;&raquo; update &laquo;&nbsp;Software\CyberLink\PowerProducer\5.0&#8243;<br
/> O4 &#8211; HKLM\..\Run: [UpdatePSTShortCut] &laquo;&nbsp;C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe&nbsp;&raquo; &laquo;&nbsp;C:\Program Files\CyberLink\DVD Suite&nbsp;&raquo; UpdateWithCreateOnce &laquo;&nbsp;Software\CyberLink\PowerStarter&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [UCam_Menu] &laquo;&nbsp;C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe&nbsp;&raquo; &laquo;&nbsp;C:\Program Files\CyberLink\YouCam&nbsp;&raquo; UpdateWithCreateOnce &laquo;&nbsp;Software\CyberLink\YouCam\2.0&#8243;<br
/> O4 &#8211; HKLM\..\Run: [GrooveMonitor] &laquo;&nbsp;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe<br
/> O4 &#8211; HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe<br
/> O4 &#8211; HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe<br
/> O4 &#8211; HKLM\..\Run: [Adobe Reader Speed Launcher] &laquo;&nbsp;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [Adobe ARM] &laquo;&nbsp;C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [QuickTime Task] &laquo;&nbsp;C:\Program Files\QuickTime\QTTask.exe&nbsp;&raquo; -atboottime<br
/> O4 &#8211; HKLM\..\Run: [iTunesHelper] &laquo;&nbsp;C:\Program Files\iTunes\iTunesHelper.exe&nbsp;&raquo;<br
/> O4 &#8211; HKCU\..\Run: [swg] &laquo;&nbsp;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&nbsp;&raquo;<br
/> O4 &#8211; HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br
/> O4 &#8211; HKCU\..\Run: [YVIBBBHA8C] C:\Users\Quentin\AppData\Local\Temp\Zfh.exe<br
/> O4 &#8211; Global Startup: BTTray.lnk = ?<br
/> O9 &#8211; Extra button: Envoyer Ã  OneNote &#8211; {2670000A-7350-4f3c-8081-5663EE0C6C49} &#8211; C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br
/> O9 &#8211; Extra &#8216;Tools&#8217; menuitem: &amp;Envoyer Ã  OneNote &#8211; {2670000A-7350-4f3c-8081-5663EE0C6C49} &#8211; C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br
/> O9 &#8211; Extra button: Research &#8211; {92780B25-18CC-41C8-B9BE-3C9C571A8263} &#8211; C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br
/> O9 &#8211; Extra button: @btrez.dll,-4015 &#8211; {CCA281CA-C863-46ef-9331-5C8D4460577F} &#8211; C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br
/> O9 &#8211; Extra &#8216;Tools&#8217; menuitem: @btrez.dll,-12650 &#8211; {CCA281CA-C863-46ef-9331-5C8D4460577F} &#8211; C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br
/> O13 &#8211; Gopher Prefix:<br
/> O18 &#8211; Protocol: avgsecuritytoolbar &#8211; {F2DDE6B2-9684-4A55-86D4-E255E237B77C} &#8211; C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll<br
/> O18 &#8211; Protocol: grooveLocalGWS &#8211; {88FED34C-F0CA-4636-A375-3CB6248B04CD} &#8211; C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br
/> O18 &#8211; Protocol: linkscanner &#8211; {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} &#8211; C:\Program Files\AVG\AVG9\avgpp.dll<br
/> O18 &#8211; Protocol: skype4com &#8211; {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} &#8211; C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br
/> O20 &#8211; AppInit_DLLs: avgrsstx.dll<br
/> O23 &#8211; Service: Apple Mobile Device &#8211; Apple Inc. &#8211; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br
/> O23 &#8211; Service: AVG Security Toolbar Service &#8211; Unknown owner &#8211; C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe<br
/> O23 &#8211; Service: AVG Free WatchDog (avg9wd) &#8211; AVG Technologies CZ, s.r.o. &#8211; C:\Program Files\AVG\AVG9\avgwdsvc.exe<br
/> O23 &#8211; Service: Service Bonjour (Bonjour Service) &#8211; Apple Inc. &#8211; C:\Program Files\Bonjour\mDNSResponder.exe<br
/> O23 &#8211; Service: Bluetooth Service (btwdins) &#8211; Broadcom Corporation. &#8211; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br
/> O23 &#8211; Service: IntelÂ® PROSet/Wireless Event Log (EvtEng) &#8211; Intel(R) Corporation &#8211; C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br
/> O23 &#8211; Service: Google Software Updater (gusvc) &#8211; Google &#8211; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br
/> O23 &#8211; Service: Service de lâ€™iPod (iPod Service) &#8211; Apple Inc. &#8211; C:\Program Files\iPod\bin\iPodService.exe<br
/> O23 &#8211; Service: NVIDIA Display Driver Service (nvsvc) &#8211; NVIDIA Corporation &#8211; C:\Windows\system32\nvvsvc.exe<br
/> O23 &#8211; Service: IntelÂ® PROSet/Wireless Registry Service (RegSrvc) &#8211; Intel(R) Corporation &#8211; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br
/> O23 &#8211; Service: Rezip &#8211; Unknown owner &#8211; C:\Windows\SYSTEM32\Rezip.exe<br
/> O23 &#8211; Service: Cyberlink RichVideo Service(CRVS) (RichVideo) &#8211; Unknown owner &#8211; C:\Program Files\CyberLink\Shared files\RichVideo.exe</p><p>&#8211;<br
/> End of file &#8211; 9872 bytes</p> ]]></content:encoded> </item> <item><title>Par : carpentier</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-128575</link> <dc:creator>carpentier</dc:creator> <pubDate>Fri, 12 Feb 2010 17:24:05 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-128575</guid> <description>Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Intel\Privacy Icon\UNS\UNS.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe</description> <content:encoded><![CDATA[<p>Running processes:<br
/> C:\WINDOWS\System32\smss.exe<br
/> C:\WINDOWS\system32\winlogon.exe<br
/> C:\WINDOWS\system32\services.exe<br
/> C:\WINDOWS\system32\lsass.exe<br
/> C:\WINDOWS\system32\svchost.exe<br
/> C:\WINDOWS\System32\svchost.exe<br
/> C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br
/> C:\Program Files\Alwil Software\Avast4\ashServ.exe<br
/> C:\WINDOWS\Explorer.EXE<br
/> C:\WINDOWS\system32\spoolsv.exe<br
/> C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br
/> C:\Program Files\Intel\ASF Agent\ASFAgent.exe<br
/> C:\Program Files\Java\jre6\bin\jqs.exe<br
/> C:\Program Files\Intel\AMT\LMS.exe<br
/> C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br
/> C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe<br
/> C:\WINDOWS\system32\svchost.exe<br
/> C:\Program Files\Fichiers communs\Intel\Privacy Icon\UNS\UNS.exe<br
/> C:\WINDOWS\system32\SearchIndexer.exe<br
/> C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br
/> C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br
/> C:\WINDOWS\system32\wbem\wmiapsrv.exe<br
/> C:\WINDOWS\System32\svchost.exe<br
/> C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br
/> C:\WINDOWS\system32\SearchProtocolHost.exe</p> ]]></content:encoded> </item> <item><title>Par : violas</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-55649</link> <dc:creator>violas</dc:creator> <pubDate>Sat, 14 Feb 2009 19:43:08 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-55649</guid> <description>Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:33:55, on 14/02/2009
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\LVComS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\WINDOWS\System32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\petiitmbert thomas\Local Settings\Temporary Internet Files\Content.IE5\41U74T6N\HiJackThis[1].exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.fr/spbasic.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: VMN Toolbar - {A057A204-BACC-4D26-8287-79A187E26987} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: VMN Toolbar - {A057A204-BACC-4D26-8287-79A187E26987} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [EPSON Stylus C62 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P33 &quot;EPSON Stylus C62 Series (Copie 1)&quot; /O6 &quot;USB001&quot; /M &quot;Stylus C62&quot;
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 &quot;EPSON Stylus C62 Series&quot; /O6 &quot;USB001&quot; /M &quot;Stylus C62&quot;
O4 - HKLM\..\Run: [WinampAgent] &quot;C:\Program Files\Winamp\winampa.exe&quot;
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files\Java\jre6\bin\jusched.exe&quot;
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] &quot;C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe&quot; /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\MSN Messenger\MsnMsgr.Exe&quot; /background
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [DAEMON Tools] &quot;E:\Thomas\Mes programmes\deamon\DAEMON Tools\daemon.exe&quot; -lang 1033
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &#039;SERVICE LOCAL&#039;)
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &#039;SERVICE RÃ‰SEAU&#039;)
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &#039;SYSTEM&#039;)
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &#039;Default user&#039;)
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&amp;xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - E:\Thomas\Mes programmes\PokerStars\PokerStarsUpdate.exe
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_1_1_0.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\System32\PnkBstrB.exe
--
End of file - 7633 bytes</description> <content:encoded><![CDATA[<p>Logfile of Trend Micro HijackThis v2.0.2<br
/> Scan saved at 20:33:55, on 14/02/2009<br
/> Platform: Windows XP  (WinNT 5.01.2600)<br
/> MSIE: Internet Explorer v6.00 (6.00.2600.0000)<br
/> Boot mode: Normal</p><p>Running processes:<br
/> C:\WINDOWS\System32\smss.exe<br
/> C:\WINDOWS\system32\csrss.exe<br
/> C:\WINDOWS\system32\winlogon.exe<br
/> C:\WINDOWS\system32\services.exe<br
/> C:\WINDOWS\system32\lsass.exe<br
/> C:\WINDOWS\system32\svchost.exe<br
/> C:\WINDOWS\System32\svchost.exe<br
/> C:\WINDOWS\System32\svchost.exe<br
/> C:\WINDOWS\System32\svchost.exe<br
/> C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br
/> C:\Program Files\Alwil Software\Avast4\ashServ.exe<br
/> C:\WINDOWS\Explorer.EXE<br
/> C:\WINDOWS\system32\spoolsv.exe<br
/> C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br
/> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE<br
/> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE<br
/> C:\Program Files\Logitech\Video\LogiTray.exe<br
/> C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe<br
/> C:\Program Files\Java\jre6\bin\jusched.exe<br
/> C:\WINDOWS\SOUNDMAN.EXE<br
/> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe<br
/> C:\WINDOWS\System32\ctfmon.exe<br
/> C:\Program Files\SuperCopier2\SuperCopier2.exe<br
/> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br
/> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br
/> C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe<br
/> C:\Program Files\Java\jre6\bin\jqs.exe<br
/> C:\WINDOWS\System32\LVComS.exe<br
/> C:\WINDOWS\System32\svchost.exe<br
/> C:\WINDOWS\System32\svchost.exe<br
/> C:\WINDOWS\System32\PnkBstrA.exe<br
/> C:\WINDOWS\System32\PnkBstrB.exe<br
/> C:\WINDOWS\System32\svchost.exe<br
/> C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe<br
/> C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br
/> C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br
/> C:\WINDOWS\System32\wbem\wmiapsrv.exe<br
/> C:\WINDOWS\System32\wbem\wmiprvse.exe<br
/> C:\WINDOWS\System32\msiexec.exe<br
/> C:\Program Files\Internet Explorer\iexplore.exe<br
/> C:\Documents and Settings\petiitmbert thomas\Local Settings\Temporary Internet Files\Content.IE5\41U74T6N\HiJackThis[1].exe</p><p>R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a
target="_blank" href="http://search.msn.fr/spbasic.htm"  rel="nofollow">http://search.msn.fr/spbasic.htm</a><br
/> R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a
target="_blank" href="http://www.google.fr/"  rel="nofollow">http://www.google.fr/</a><br
/> R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens<br
/> O2 &#8211; BHO: AcroIEHelperStub &#8211; {18DF081C-E8AD-4283-A596-FA578C2EBDC3} &#8211; C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br
/> O2 &#8211; BHO: Java(tm) Plug-In SSV Helper &#8211; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} &#8211; C:\Program Files\Java\jre6\bin\ssv.dll<br
/> O2 &#8211; BHO: VMN Toolbar &#8211; {A057A204-BACC-4D26-8287-79A187E26987} &#8211; C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL<br
/> O2 &#8211; BHO: Java(tm) Plug-In 2 SSV Helper &#8211; {DBC80044-A445-435b-BC74-9C25C1C588A9} &#8211; C:\Program Files\Java\jre6\bin\jp2ssv.dll<br
/> O2 &#8211; BHO: JQSIEStartDetectorImpl &#8211; {E7E6F031-17CE-4C07-BC86-EABFE594F69C} &#8211; C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br
/> O3 &#8211; Toolbar: VMN Toolbar &#8211; {A057A204-BACC-4D26-8287-79A187E26987} &#8211; C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL<br
/> O3 &#8211; Toolbar: &amp;Radio &#8211; {8E718888-423F-11D2-876E-00A0C9082467} &#8211; C:\WINDOWS\System32\msdxm.ocx<br
/> O4 &#8211; HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br
/> O4 &#8211; HKLM\..\Run: [EPSON Stylus C62 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P33 &laquo;&nbsp;EPSON Stylus C62 Series (Copie 1)&nbsp;&raquo; /O6 &laquo;&nbsp;USB001&#8243; /M &laquo;&nbsp;Stylus C62&#8243;<br
/> O4 &#8211; HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 &laquo;&nbsp;EPSON Stylus C62 Series&nbsp;&raquo; /O6 &laquo;&nbsp;USB001&#8243; /M &laquo;&nbsp;Stylus C62&#8243;<br
/> O4 &#8211; HKLM\..\Run: [WinampAgent] &laquo;&nbsp;C:\Program Files\Winamp\winampa.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br
/> O4 &#8211; HKLM\..\Run: [nwiz] nwiz.exe /install<br
/> O4 &#8211; HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br
/> O4 &#8211; HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe<br
/> O4 &#8211; HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe<br
/> O4 &#8211; HKLM\..\Run: [Adobe Reader Speed Launcher] &laquo;&nbsp;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [SunJavaUpdateSched] &laquo;&nbsp;C:\Program Files\Java\jre6\bin\jusched.exe&nbsp;&raquo;<br
/> O4 &#8211; HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot<br
/> O4 &#8211; HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br
/> O4 &#8211; HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br
/> O4 &#8211; HKLM\..\Run: [!AVG Anti-Spyware] &laquo;&nbsp;C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe&nbsp;&raquo; /minimized<br
/> O4 &#8211; HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe<br
/> O4 &#8211; HKCU\..\Run: [MsnMsgr] &laquo;&nbsp;C:\Program Files\MSN Messenger\MsnMsgr.Exe&nbsp;&raquo; /background<br
/> O4 &#8211; HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe<br
/> O4 &#8211; HKCU\..\Run: [DAEMON Tools] &laquo;&nbsp;E:\Thomas\Mes programmes\deamon\DAEMON Tools\daemon.exe&nbsp;&raquo; -lang 1033<br
/> O4 &#8211; HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S<br
/> O4 &#8211; HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &#8216;SERVICE LOCAL&#8217<img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_wink.gif" alt="" /><br
/> O4 &#8211; HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &#8216;SERVICE RÃ‰SEAU&#8217<img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_wink.gif" alt="" /><br
/> O4 &#8211; HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &#8216;SYSTEM&#8217<img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_wink.gif" alt="" /><br
/> O4 &#8211; HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User &#8216;Default user&#8217<img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_wink.gif" alt="" /><br
/> O4 &#8211; Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br
/> O4 &#8211; Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br
/> O8 &#8211; Extra context menu item: E&amp;xporter vers Microsoft Excel &#8211; res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br
/> O9 &#8211; Extra button: PokerStars.net &#8211; {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} &#8211; E:\Thomas\Mes programmes\PokerStars\PokerStarsUpdate.exe<br
/> O16 &#8211; DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) &#8211; <a
target="_blank" href="http://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_1_1_0.cab"  rel="nofollow">http://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_1_1_0.cab</a><br
/> O16 &#8211; DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) &#8211; <a
target="_blank" href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab"  rel="nofollow">http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab</a><br
/> O23 &#8211; Service: Planificateur Avira AntiVir Personal &#8211; Free Antivirus (AntiVirScheduler) &#8211; Avira GmbH &#8211; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe<br
/> O23 &#8211; Service: Avira AntiVir Personal &#8211; Free Antivirus Guard (AntiVirService) &#8211; Avira GmbH &#8211; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe<br
/> O23 &#8211; Service: avast! iAVS4 Control Service (aswUpdSv) &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br
/> O23 &#8211; Service: avast! Antivirus &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\ashServ.exe<br
/> O23 &#8211; Service: avast! Mail Scanner &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br
/> O23 &#8211; Service: avast! Web Scanner &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br
/> O23 &#8211; Service: AVG Anti-Spyware Guard &#8211; GRISOFT s.r.o. &#8211; C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br
/> O23 &#8211; Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) &#8211; SEIKO EPSON CORPORATION &#8211; C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe<br
/> O23 &#8211; Service: Java Quick Starter (JavaQuickStarterService) &#8211; Sun Microsystems, Inc. &#8211; C:\Program Files\Java\jre6\bin\jqs.exe<br
/> O23 &#8211; Service: Ma-Config Service (maconfservice) &#8211; CybelSoft &#8211; C:\Program Files\ma-config.com\maconfservice.exe<br
/> O23 &#8211; Service: NVIDIA Display Driver Service (NVSvc) &#8211; NVIDIA Corporation &#8211; C:\WINDOWS\System32\nvsvc32.exe<br
/> O23 &#8211; Service: PnkBstrA &#8211; Unknown owner &#8211; C:\WINDOWS\System32\PnkBstrA.exe<br
/> O23 &#8211; Service: PnkBstrB &#8211; Unknown owner &#8211; C:\WINDOWS\System32\PnkBstrB.exe</p><p>&#8211;<br
/> End of file &#8211; 7633 bytes</p> ]]></content:encoded> </item> <item><title>Par : Ogu</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16902</link> <dc:creator>Ogu</dc:creator> <pubDate>Wed, 27 Feb 2008 15:04:58 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16902</guid> <description>Salut Ã  tous!
Je venais poster pour ZHP dÃ©veloppÃ© par Coolman de l&#039;Espace SÃ©curitÃ© de ZEbulon, mais Falkra a dÃ©jÃ  fait le taff!
Falkra, je savais pas que tu passais aussi chez Korben !</description> <content:encoded><![CDATA[<p>Salut Ã  tous!</p><p>Je venais poster pour ZHP dÃ©veloppÃ© par Coolman de l&#8217;Espace SÃ©curitÃ© de ZEbulon, mais Falkra a dÃ©jÃ  fait le taff!</p><p>Falkra, je savais pas que tu passais aussi chez Korben !</p> ]]></content:encoded> </item> <item><title>Par : admin</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16840</link> <dc:creator>admin</dc:creator> <pubDate>Tue, 26 Feb 2008 23:07:30 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16840</guid> <description>Ouais, c&#039;est ma source Loki :-)
Par contre, PrevX je l&#039;ai virÃ© de la liste car tout naze et pas fiable</description> <content:encoded><![CDATA[<p>Ouais, c&#8217;est ma source Loki <img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_smile.gif" alt="" /><br
/> Par contre, PrevX je l&#8217;ai virÃ© de la liste car tout naze et pas fiable</p> ]]></content:encoded> </item> <item><title>Par : Loki</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16838</link> <dc:creator>Loki</dc:creator> <pubDate>Tue, 26 Feb 2008 22:40:59 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16838</guid> <description>Il y en a un des deux qui c&#039;est inspirÃ© de l&#039;autre ou quoi?Regardez sur ce blog!C&#039;est le mÃªme article!!! (en passant par une traduction bien entendus.)
http://www.raymond.cc/blog/archives/2008/02/25/5-ways-to-automatically-analyze-hijackthis-log-file/
Oups! Pas de bol on dirais son article date du 25 :-p!
Vous avez la mÃªme source d&#039;info?
On y propose encore un autre moyen pour dÃ©chiffrer les logs hijhack(pratique il suffit de copier coller le log et de faire analyser!)
http://www.prevx.com/hijackthis.asp</description> <content:encoded><![CDATA[<p>Il y en a un des deux qui c&#8217;est inspirÃ© de l&#8217;autre ou quoi?Regardez sur ce blog!C&#8217;est le mÃªme article!!! (en passant par une traduction bien entendus.)</p><p><a
target="_blank" href="http://www.raymond.cc/blog/archives/2008/02/25/5-ways-to-automatically-analyze-hijackthis-log-file/"  rel="nofollow">http://www.raymond.cc/blog/archives/2008/02/25/5-ways-to-automatically-analyze-hijackthis-log-file/</a></p><p>Oups! Pas de bol on dirais son article date du 25 :-p!</p><p>Vous avez la mÃªme source d&#8217;info?</p><p>On y propose encore un autre moyen pour dÃ©chiffrer les logs hijhack(pratique il suffit de copier coller le log et de faire analyser!)</p><p><a
target="_blank" href="http://www.prevx.com/hijackthis.asp"  rel="nofollow">http://www.prevx.com/hijackthis.asp</a></p> ]]></content:encoded> </item> <item><title>Par : admin</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16825</link> <dc:creator>admin</dc:creator> <pubDate>Tue, 26 Feb 2008 20:10:09 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16825</guid> <description>@bambamsfr : Moins pire que les 2 premiÃ¨res sauf que ma dentiste a trop galÃ¨rÃ© et a mis 1h pour m&#039;en sortir 1 seule ! Truc de fou quoi... Enfin, c&#039;est sympa de prendre des news !</description> <content:encoded><![CDATA[<p>@bambamsfr : Moins pire que les 2 premiÃ¨res sauf que ma dentiste a trop galÃ¨rÃ© et a mis 1h pour m&#8217;en sortir 1 seule ! Truc de fou quoi&#8230; Enfin, c&#8217;est sympa de prendre des news !</p> ]]></content:encoded> </item> <item><title>Par : bambamsfr</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16824</link> <dc:creator>bambamsfr</dc:creator> <pubDate>Tue, 26 Feb 2008 20:02:51 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16824</guid> <description>Salut Korben,
J&#039;ai pas lu tous les commentaires (ouah la honte !!) depuis hier, mais c&#039;Ã©tait comme les dents de sagesse ??</description> <content:encoded><![CDATA[<p>Salut Korben,</p><p>J&#8217;ai pas lu tous les commentaires (ouah la honte !!) depuis hier, mais c&#8217;Ã©tait comme les dents de sagesse ??</p> ]]></content:encoded> </item> <item><title>Par : Diti</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16819</link> <dc:creator>Diti</dc:creator> <pubDate>Tue, 26 Feb 2008 19:43:11 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16819</guid> <description>Quand je vois ce genre de programmes, je me dis, avec du recul, que toutes ces histoires de virus m&#039;auront quand mÃªme bien fait chier une bonne partie de ma vie :) .</description> <content:encoded><![CDATA[<p>Quand je vois ce genre de programmes, je me dis, avec du recul, que toutes ces histoires de virus m&#8217;auront quand mÃªme bien fait chier une bonne partie de ma vie <img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_smile.gif" alt="" /> .</p> ]]></content:encoded> </item> <item><title>Par : Carez</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16816</link> <dc:creator>Carez</dc:creator> <pubDate>Tue, 26 Feb 2008 19:25:30 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16816</guid> <description></description> <content:encoded><![CDATA[<p>Merci korben, depuis le temps que je galÃ©re pour interprÃ©ter mes logs correctement <img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_wink.gif" alt="" /><br
/> <a
target="_blank" href="http://www.geekornot.fr"  rel="nofollow">http://www.geekornot.fr</a> si tu veux jeter un coup d&#8217;Å?il ^^</p> ]]></content:encoded> </item> <item><title>Par : Etan</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16803</link> <dc:creator>Etan</dc:creator> <pubDate>Tue, 26 Feb 2008 17:24:42 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16803</guid> <description>Il existe aussi exeLibrary (http://exelib.com/)dont j&#039;ai parlÃ© il y a quelques jours:
http://www.etanonline.powa.fr/2008/exelibrary-explicitez-les-processus-de-windows/
Il recense les processus windows, apporte des infos et propose d&#039;analyser les logs HiJackThis.</description> <content:encoded><![CDATA[<p>Il existe aussi exeLibrary (<a
target="_blank" href="http://exelib.com/"  rel="nofollow">http://exelib.com/</a>)dont j&#8217;ai parlÃ© il y a quelques jours:<br
/> <a
target="_blank" href="http://www.etanonline.powa.fr/2008/exelibrary-explicitez-les-processus-de-windows/"  rel="nofollow">http://www.etanonline.powa.fr/2008/exelibrary-explicitez-les-processus-de-windows/</a></p><p>Il recense les processus windows, apporte des infos et propose d&#8217;analyser les logs HiJackThis.</p> ]]></content:encoded> </item> <item><title>Par : admin</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16801</link> <dc:creator>admin</dc:creator> <pubDate>Tue, 26 Feb 2008 17:18:03 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16801</guid> <description>Merci Falkra ! C&#039;est frenchy en plus ! Cool :-)</description> <content:encoded><![CDATA[<p>Merci Falkra ! C&#8217;est frenchy en plus ! Cool <img
src="http://korben.info/wp-content/plugins/wp-smiley-switcher/yellowpack/icon_smile.gif" alt="" /></p> ]]></content:encoded> </item> <item><title>Par : Falkra</title><link>http://korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html/comment-page-1#comment-16799</link> <dc:creator>Falkra</dc:creator> <pubDate>Tue, 26 Feb 2008 17:06:43 +0000</pubDate> <guid
isPermaLink="false">http://www.korben.info/4-outils-pour-analyser-les-logs-de-hijackthis.html#comment-16799</guid> <description>Bonjour Korben, il existe un 5eme moyen, avec des mises Ã  jour trÃ¨s frÃ©quentes, et plus Ã  jour cÃ´tÃ© base de donnÃ©es que d&#039;autres : Zeb Help Process, de Coolman.
Si tu veux jeter un coup d&#039;oeil :
http://www.libellules.ch/dotclear/index.php?2008/02/23/2447-zeb-help-process</description> <content:encoded><![CDATA[<p>Bonjour Korben, il existe un 5eme moyen, avec des mises Ã  jour trÃ¨s frÃ©quentes, et plus Ã  jour cÃ´tÃ© base de donnÃ©es que d&#8217;autres : Zeb Help Process, de Coolman.<br
/> Si tu veux jeter un coup d&#8217;oeil :<br
/> <a
target="_blank" href="http://www.libellules.ch/dotclear/index.php?2008/02/23/2447-zeb-help-process"  rel="nofollow">http://www.libellules.ch/dotclear/index.php?2008/02/23/2447-zeb-help-process</a></p> ]]></content:encoded> </item> </channel> </rss>
